This study aims to analyze the legal regulation of biometric data protection in digital identity verification systems in Indonesia, identify existing juridical problems and normative gaps, and formulate an ideal legal reconstruction model. The research employs a normative juridical method using statutory and conceptual approaches. The findings indicate that although Indonesia has established a legal framework through Law Number 27 of 2022 concerning Personal Data Protection, Government Regulation Number 71 of 2019, and constitutional guarantees under Article 28G paragraph (1) of the 1945 Constitution, significant regulatory deficiencies remain. Major issues include inadequate consent mechanisms, the absence of specific standards for biometric data retention and deletion, limited algorithm auditing, and weak accountability for data breaches. These deficiencies create a normative gap between technological development and legal protection. This study proposes a legal reconstruction model emphasizing meaningful consent, risk-based regulation, independent algorithm auditing, strict liability, independent supervision, and the implementation of privacy by design and accountability by design to strengthen legal certainty, privacy protection, and public trust in the digital era.
Copyrights © 2026